CVE-2026-73332

Source
https://cve.org/CVERecord?id=CVE-2026-73332
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-73332.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-73332
Published
2026-08-12T19:09:47.600Z
Modified
2026-08-15T04:07:21.733367946Z
Severity
  • 9.2 (Critical) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:A/VC:H/VI:H/VA:N/SC:H/SI:H/SA:N CVSS Calculator
Summary
CamaleonCMS cama_contact_form Plugin Stored XSS via before_html Field
Details

CamaleonCMS contains a stored cross-site scripting vulnerability in the camacontactform plugin that allows low-privileged authenticated attackers to inject arbitrary HTML by submitting unsanitized content to the before_html field through the contact form edit endpoint, which lacks proper authorization controls. Attackers can persist malicious script payloads into the database that execute in victims' browsers when the contact form loads, enabling cookie theft, forged authenticated requests against the admin interface, and session takeover of viewing users.

Database specific
{
    "cwe_ids": [
        "CWE-89"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/73xxx/CVE-2026-73332.json",
    "cna_assigner": "VulnCheck"
}
References

Affected packages

Git / github.com/owen2345/camaleon-cms

Affected ranges

Type
GIT
Repo
https://github.com/owen2345/camaleon-cms
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected
Database specific
Show details
{
    "extracted_events": [
        {
            "introduced": "0"
        },
        {
            "last_affected": "2.9.1"
        }
    ],
    "source": "AFFECTED_FIELD"
}

Affected versions

0.*
0.1.7
0.2.0
2.*
2.1.1
2.1.2
2.1.2.0
2.2.0
2.3.1
2.3.2
2.3.3
2.3.4
2.3.5
2.3.6
2.3.7
2.4.0
2.4.1
2.4.2
2.4.3
2.4.3.10
2.4.3.11
2.4.3.12
2.4.3.7
2.4.4
2.4.4.2
2.4.4.3
2.4.4.5
2.4.4.6
2.4.5
2.4.5.1
2.4.5.10
2.4.5.11
2.4.5.12
2.4.5.13
2.4.5.14
2.4.5.7
2.4.6.0
2.4.6.1
2.4.6.7
2.5.1
2.5.3
2.5.3.1
2.6.0
2.6.0.1
2.6.1
2.6.2
2.6.4
2.7.0
2.7.1
2.7.3
2.7.4
2.7.5
2.8.0
2.8.1
2.8.2
2.8.3
2.9.0
2.9.1
camaleon_cms-2.*
camaleon_cms-2.4.5.11.gem
v2.*
v2.0.0
v2.1.1.3

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-73332.json"